CVE-2025-13320Medium· 6.8▾ SunlitThe WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combin…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server via the 'current_user_avatar' parameter in a two-stage attack which can make remote code execution possible. This only affects sites with the custom avatar setting enabled.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-26158High· 7.0A flaw was found in BusyBox
CVE-2026-26157High· 7.0A flaw was found in BusyBox
CVE-2025-12915Medium· 6.4A vulnerability was found in 70mai X200 up to 20251019
CVE-2025-66449High· 8.8ConvertXis a self-hosted online file converter
CVE-2021-21343Medium· 5.3XStream is a Java library to serialize objects to XML and back again
CVE-2026-106559Medium· 6.3Backstage is an open framework for building developer portals